ISO 45001: what it means for workplace safety?

A company may already have risk assessments, method statements, training records and accident reports. On paper, health and safety exists. The real question starts when ISO 45001 comes up: is it just a certificate for tenders, or is it a different way of managing risk across the business?

ISO 45001 does not replace health and safety law, and it is not a one-off training exercise. It is an international standard for an occupational health and safety management system. It helps an organisation set up a structured way to identify hazards, assess risks, involve workers, control contractors, respond to incidents and check whether safety is working in real life, not only in files. ISO 45001:2018 remains the main international standard, with a 2024 amendment adding climate action considerations to management system requirements.

What is ISO 45001 and what should it not be confused with?

ISO 45001 is a management system standard. It does not apply to one machine, one workstation or one product. It is not a personal qualification for a health and safety adviser. It describes how an organisation manages occupational health and safety: leadership, planning, hazard identification, worker participation, legal requirements, operational control, emergency planning, monitoring and improvement.

That should not be reduced to “we have health and safety covered”. Most businesses have some health and safety duties and documents. ISO 45001 goes further. It asks whether the organisation can show a system: who makes decisions, how hazards are reported, how risk is assessed, what happens after an incident, how contractors are controlled and how the business knows whether its controls are actually working.

The standard is not a ready-made folder of procedures. Documents matter, but documents alone do not make a system. If people on the shop floor, construction site or warehouse work differently from the procedure, an audit will quickly show the gap between paperwork and reality.

ISO 45001:2018, BS ISO 45001 and the 2024 amendment

The main reference is ISO 45001:2018, the international standard for occupational health and safety management systems. In British documentation it is commonly seen as BS ISO 45001, because the ISO standard is adopted as a British Standard.

ISO 45001 replaced OHSAS 18001 as the recognised international standard for OH&S management systems. Organisations that still refer to OHSAS 18001 in old files, supplier questionnaires or tender documents should treat that as outdated language and check what the client or certification body now expects.

In 2024, ISO issued an amendment connected with climate action across management system standards. For ISO 45001 this does not turn the standard into an environmental standard. It means organisations should consider whether climate change is relevant to the context of the organisation and to interested parties. For health and safety, that may matter where heat stress, flooding, outdoor work, severe weather, supply disruption or emergency arrangements affect workers.

The practical message is simple: use ISO 45001:2018 as the base standard, check current certification requirements, and do not treat old labels or outdated templates as enough.

What does ISO 45001 require a company to control?

There is no point turning ISO 45001 into a dry list of clauses. For a business, the more useful question is: what must be under control for the health and safety system to be credible?

AreaWhat the organisation needs to show
Scope of the systemWhich sites, activities, workers, processes and services are covered
LeadershipWho takes health and safety decisions and how managers are accountable
Worker participationHow workers report hazards, raise concerns and take part in improving safety
Hazard identificationHow hazards are found during routine work, non-routine work and change
Risk assessmentHow risks to workers, contractors and others are assessed and controlled
Legal and other requirementsHow the organisation identifies and keeps up with applicable duties
Contractors and outsourcingHow external work is selected, controlled and reviewed
Emergency preparednessHow the organisation prepares for accidents, failures and abnormal events
MonitoringHow the business checks whether controls are working
ImprovementWhat changes after incidents, audits, inspections and worker feedback

This is not a tick-box list for the week before an audit. Each area has to show up in the way the organisation works. If workers stop reporting hazards because nothing ever happens afterwards, the reporting form is not doing much.

The first step is to understand where risk is created. Only then can the company judge whether its current health and safety documents are enough, or whether they are just a set of files that no longer match the work being done in production, construction, logistics or service operations.

Where ISO 45001 makes the most sense

ISO 45001 can be used by organisations of different sizes and sectors. It is not only for large industrial groups. The value depends less on headcount and more on risk, complexity, contractor use, customer expectations and how much work changes from day to day.

The difference becomes clearer where risk is not limited to an office desk. Manufacturing, construction, logistics, energy, warehousing, maintenance, technical service, work at height, internal transport and contractor-heavy activities all need safety controls that work under changing conditions.

Type of organisation or workWhy ISO 45001 can help
Manufacturing siteRisk comes from machinery, energy, maintenance, internal transport and process changes
Construction contractorWorkplaces change and many risks depend on coordination between contractors
Warehouse or logistics operationPedestrians, forklifts, loading areas, time pressure and traffic routes need active control
Utilities and maintenanceWork may involve isolation, faults, height, confined spaces or permit-to-work systems
Service companyWorkers often operate on customer sites where conditions are not fully controlled by their employer
Business using contractorsRisk can be created by people who are not direct employees but still work under the organisation’s influence

An office-based business may still want ISO 45001 because a customer, parent company or tender asks for it. But the standard has the most substance where safety depends on daily decisions made by supervisors, operators, drivers, engineers, contractors and managers, not only on a signed procedure.

Contractors, service work and work on customer sites

This is one of the areas that gets missed. A company may have good arrangements at its own site, while the real risk appears elsewhere. A technician visits a customer. A team works on a live construction site. A contractor enters a factory for maintenance. A driver unloads in someone else’s yard.

ISO 45001 expects the organisation to look beyond its own employees. The system should consider workers performing work under the organisation’s control, contractors, outsourced activities and other people who may be affected by what the organisation does.

That changes the way health and safety is managed. A generic risk assessment for “warehouse operative” or “maintenance engineer” may not be enough. The business has to understand non-routine work, breakdowns, contractor access, changes to traffic routes, new substances, new equipment and new ways of working.

A new machine is not only a technical investment. It can introduce new hazards, new guarding needs, new training, new maintenance routines and new emergency arrangements. A working ISO 45001 system should pick that up before the problem lands on the shop floor.

Is ISO 45001 useful for tenders and B2B work?

For some companies, ISO 45001 starts with a customer requirement. A certificate may be requested in a tender, supplier approval process or framework agreement. This is common where work is carried out on client sites or where the contractor’s activities can affect other people.

The certificate can therefore have commercial value. But if it is treated only as a paper exercise, the weakness will show up when the client asks harder questions. Who supervises subcontractors? How are near misses reviewed? How do workers raise hazards? What changed after the last incident? How are non-routine tasks controlled?

Certification can confirm that a management system has been assessed against the standard. It does not run the system for the company. Daily control still comes from leadership, supervision, worker involvement, contractor management, change control and follow-up after things go wrong.

Common mistakes when implementing ISO 45001

The first mistake is treating ISO 45001 as a documentation project. Someone buys templates, adds the company name and assumes the system is ready. That may survive until the first worker interview or the first walk-through on site.

The second mistake is putting the whole system on the health and safety manager. ISO 45001 relies on leadership, accountability and worker participation. If directors and line managers treat it as “the safety person’s job”, risk management will not properly bed in.

The third mistake is failing to manage change. A risk assessment written once and left in a folder quickly falls behind. A new process, material, layout, contractor, shift pattern or traffic route can create risks that were not in the old documents.

The fourth mistake is ignoring contractors. In many businesses, the most difficult incidents arise from maintenance, installation, transport, cleaning, refurbishment or temporary work. If the system does not cover those activities, the gap is serious.

The fifth mistake is not responding to worker feedback. Someone reports a slippery floor, a blind spot near forklifts, a damaged guard or pressure to bypass a control. If nothing happens, people stop reporting. The system stays on paper.

ISO 45001 and ordinary health and safety documentation

Health and safety documentation can exist without ISO 45001. A company may have risk assessments, training records, accident forms, safe systems of work, inspection sheets and emergency procedures. That does not automatically mean it has a functioning OH&S management system.

A system starts when documents are connected to decisions. Someone reviews hazard reports. Someone checks whether corrective actions were completed. Someone speaks to workers. Someone updates risk controls after a process change. Someone assesses a contractor by how the work will be done, not only by price and availability.

ISO 45001 is built around a process approach. It covers consultation and participation, planning, hazard identification, risk control, legal requirements, communication, operational control, management of change, procurement, contractors, emergency preparedness, audits and improvement. That is why it should not be treated as an extra file in the health and safety folder. It is a way of running risk control across the business.

FAQ: ISO 45001 and workplace safety

Is ISO 45001 mandatory?

No, not as a general legal requirement for every business. It may still be required by a customer, tender, contract, parent company or internal policy. Whether certified or not, the organisation must still meet the health and safety law that applies to its activities.

Does ISO 45001 replace health and safety law?

No. ISO 45001 helps organise an OH&S management system, but it does not remove legal duties. The organisation still has to identify and comply with the requirements that apply to its people, workplaces, equipment, contractors and activities.

Is ISO 45001 only for large companies?

No. It can be used by organisations of different sizes and sectors. The main issue is not the number of employees, but the level of risk, process complexity, contractor use and customer expectations.

Did ISO 45001 replace OHSAS 18001?

Yes. ISO 45001 replaced OHSAS 18001 as the international standard for occupational health and safety management systems.

Does ISO 45001 certification mean a company is automatically safe?

No. Certification can show that a system has been assessed against the standard, but safety depends on everyday action: leadership, worker involvement, response to hazards, contractor control, change management and follow-up after incidents.

Summary

ISO 45001 is not a badge for neat health and safety paperwork, and certification does not make a company safe by itself. It is a way to manage occupational health and safety risk across the business: leadership, worker participation, contractors, change, incidents, corrective actions and real control of work. It makes the most sense where safety depends on many people, changing conditions and daily decisions on the shop floor, site, warehouse or service job. The starting point is not “what procedures can we write?”. It is “where does risk really arise, and who can control it?”.

0 comments
Oldest
Newest